You investigate with what you collected beforehand When an incident hits, the questions come fast: what happened, how did they get in, what did they touch, […]
A plan you have never tested is a hypothesis Many organizations have an incident response plan filed away, and assume that is enough. Then a real […]
Every year the pattern repeats, and 2025 was no exception: threat actors time major intrusions and ransomware deployments for holidays, long weekends, and year-end, precisely when […]
In August 2025, Canada’s House of Commons confirmed a data breach in which an attacker exploited a recent Microsoft vulnerability to access a database containing employee […]
Every incident investigation eventually comes down to one question: what does the evidence show? Too often the honest answer is that the evidence was never collected. […]
In October 2024, the Internet Archive suffered a data breach exposing user account information, alongside disruptive denial-of-service attacks against its services. A widely loved nonprofit with […]
On July 19, 2024, a faulty content update to CrowdStrike’s Falcon sensor caused millions of Windows machines worldwide to crash into a boot loop. Airlines, hospitals, […]